FOSSA
Automated open source dependency, license, and vulnerability management platform for controlling software supply chains
- Also known as
- fossa
Available worldwide · Popular in: US
What is FOSSA?
A platform that helps teams identify and manage open source dependencies across their codebase, enforce license compliance policies, detect and remediate security vulnerabilities, and generate regulatory-compliant software bills of materials (SBOMs).
FOSSA pricing
Plans, per-tier features and add-ons, dated and linked to live pricing. Pricing changes often; always verify at source before you rely on it.
Free plan available; Business from $20/project/month billed annually; Enterprise custom pricing
Free
FreeFor individuals and small teams getting started.
- projects
- 5
- imported_sboms
- 5
- quality_checks
- 1
- dependency_levels
- 5
- Container scanning
- Identify dependencies at any depth
- Basic email support
- API access
- SaaS (multi-tenant cloud)
- Limited Filters
- Export SBOMs
Business
For growing teams needing advanced compliance and security.
- projects
- 10
- imported_sboms
- Unlimited
- release_groups
- 1
- contributing_developers
- 10
- Everything in Free, plus:
- Unlimited imported SBOMs
- Automated license and vulnerability scanning
- Multi-project reporting
- Priority support
- Full suite of quality checks
Enterprise
Contact salesFor organizations needing custom deployment and enterprise features.
- projects
- Unlimited
- dependency_levels
- Unlimited
- Everything in Business, plus:
- Enterprise-grade SLAs
- Custom retention policies
- Advanced compliance reporting
- Enterprise-grade APIs
- Custom deployment options
- SSO
- Rules based access controls (RBAC)
Add-ons
- Snippet Scanning Add-On
- Binary Scanning Add-On
What FOSSA does
The capabilities that matter for dependency management, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.
- Update automation
- ✓
- Vuln scanning
- ✓
- Reachability analysis
- ✗
- License compliance
- ✓
- Sbom generation
- ✓
- Ci gating
- ✓
- Container image scanning
- ✓
- Auto merge policy
- ✗
- Open source
- ✓
Platform & deployment
Independently observed- CLI
- Web
- Cloud / SaaS
- On-premise
- Self-hosted
Integrations (10)
Independently observed- GitHub
- CI/CD platforms
- Gradle
- Maven
- JavaScript/TypeScript ecosystems
- Python
- Golang
- Ruby
- Rust
- Kotlin
FOSSA alternatives
Other dependency management we track, ranked by the same independent score.
- GitHub DependabotAutomatically scan dependencies for vulnerabilities and create pull requests to keep them updatedhigh · 76%
- OWASP Dependency-Tracklow · 28%
- OWASP Dependency-Checklow · 10%
- pip-auditlow · 26%
- TideliftStatic code analysis platform for identifying security vulnerabilities, quality issues, and technical debt in software developmentlow · 29%
- Sonatype LifecycleAutomatically manage open source dependencies and identify vulnerabilities across your software supply chainlow · 15%
Compare FOSSA
Side by side against other dependency management, attribute by attribute, with a source on every value.
The Vioscale score: one lens on the evidence
Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for FOSSA, not the verdict.
| Signal | Score | Weight | Contribution | Evidence |
|---|---|---|---|---|
| Capabilities | 87 | 0.05 | 4.2 | ✓ |
| Pricing transparency | 45 | 0.08 | 3.8 | ✓ |
| Security posture | 40 | 0.07 | 2.9 | ✓ |
| Price level | 50 | 0.05 | 2.6 | ✓ |
| Integrations | 30 | 0.04 | 1.2 | ✓ |
| Reliability | 0 | 0.07 | 0.0 | - |
Computed . Re-weight it by intent, or see the full method.
All data & sourcesshow ↓
Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.
Features
| Attribute | Value | Evidence |
|---|---|---|
| Capabilities | Ci gating, Open source, Vuln scanning, Sbom generation, Update automation, License compliance, Container image scanning | mediumsource · 2026-08-25 · 60% |
Integrations
| Attribute | Value | Evidence |
|---|---|---|
| Count | 10 | mediumsource · 2026-08-25 · 60% |
Market
| Attribute | Value | Evidence |
|---|---|---|
| Availability | PrimaryMarkets: … · AvailabilityScope: global · AvailableCountries: … · NotAvailableCountries: … | mediumsource · 2026-08-25 · 50% |
Pricing
Security
| Attribute | Value | Evidence |
|---|---|---|
| Soc2 | Yes | highsource · 2026-08-25 · 75% |